HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
LPL FINANCIAL LLC
bd_23641c5817d6e663 · schema v1 · pii pii-v1
Full breach record for LPL FINANCIAL LLC →LPL Financial LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 NH residents. Unauthorized access to an advisor's portal account occurred starting October 26, 2025, via a malicious script. Personal data exposed included names, SSNs, account numbers, and contact info. LPL contained the breach, worked with law enforcement, and offered 24 months of credit monitoring to affected individuals. Notification was sent June 29, 2026.
Leak gap clock✗ Leak >180d31 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cephalus about this victim predates this filing by 313 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_941f183dd2050015New Hampshire State AGfiled 2026-05-20(47d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lpl-financial-20260706.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 6, 2026
- Raw hash
- b37e2ab8273a1eec1729a1f2aa6caf5331b36771452546635f1d465e98b2f41e
Reporting entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Victim entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Incident
- Discovered
- Dec 1, 2025
- Materiality determined
- —
- Notification sent
- Jun 29, 2026
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- working with law enforcement regarding the investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(217 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.